Skip to content

Conversation

@dojoSec
Copy link

@dojoSec dojoSec commented Oct 6, 2025

No description provided.

@dojoSec dojoSec changed the title added "Accounts which do not require password for login (enabled, password can be changed)" section added "Accounts which have PasswordNotRequired set (enabled)" section Oct 7, 2025
@exploide
Copy link
Owner

exploide commented Nov 2, 2025

As discussed in person, PasswordNotRequired is not immediately a problem since it only allows a password to be blank but does not indicate that the password actualls is blank.
So we are not sure whether this really is noteworthy. 🤷‍♂️
However, I plan to restructure the audit checks anyway and perhaps we could include more curious things like that in the future.
I might come back to this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants